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We prove the security of the Bennett-Brassard (BB84) quantum key distribution protocol 
in the case where the key information is encoded in the relative phase of a coherent-state 
reference pulse and a weak coherent-state signal pulse, as in some practical implementa- 
tions of the protocol. In contrast to previous work, our proof applies even if the eaves- 
dropper knows the phase of the reference pulse, provided that this phase is not modulated 
by the source, and even if the reference pulse is bright. The proof also applies to the 
case where the key is encoded in the photon polarization of a weak coherent-state pulse 
with a known phase, but only if the phases of the four BB84 signal states are judiciously 
chosen. The achievable key generation rate scales quadratically with the transmission in 
the channel, just as for BB84 with phase-randomized weak coherent-state signals (when 
decoy states are not used) . For the case where the phase of the reference pulse is strongly 
modulated by the source, we exhibit an explicit attack that allows the eavesdropper to 
learn every key bit in a parameter regime where a protocol using phase-randomized 
signals is provably secure. 



1 Introduction 

In quantum key distribution (QKD) [T], two parties (Alice and Bob) use quantum signals 
to establish a shared key that can be used to encrypt and decrypt classical messages. An 
eavesdropper (Eve) who collects information about the key by interacting with the signals 
produces a detectable disturbance; therefore Alice and Bob can detect the eavesdropper's 
activity, and they can reject the key if they fear that the eavesdropper knows too much about 
it. But if the detected disturbance is weak enough, then Alice and Bob can use classical 
error correction and privacy amplification protocols to extract a shared key that is very 
nearly uniformly distributed and almost certainly private [2J El SI [5J ISJ [3 [8] . The security 
of the QKD protocol is said to be unconditional, because the security can be proven for 
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any attack consistent with the laws of quantum physics, and without any assumptions about 
computational hardness. 

Experiments have recently demonstrated the feasibility of QKD over 150 km telecom fibers 
[21 [10] , and at least two firms are now marketing commercial QKD systems [TTj . But how 
secure are these systems, really? To assess the security of practical implementations of QKD, 
it is important to consider how well the actual systems match the performance assumed in 
the security proofs. In particular, the signals used in typical practical realizations of QKD 
are dim laser pulses, which occasionally contain more than one photon. Multi-photon signals 
together with loss in the optical fiber can threaten security, but proofs of security for QKD 
using weak coherent states have been found [TJ] [T3] . (We note that for QKD protocols that 
use decoy states [HJ [TJ3 [T5], security can be proven even for rather strong coherent-state 
signals. In this paper, however, we will focus on QKD with weak coherent states.) 

A key assumption in the security proofs in rTJjrjJ] (and also in [T5]) is that the phase of 
the quantum signal is uniformly random. A coherent state of one mode of the electromagnetic 
field can be expressed as 



where \n) denotes the state with photon number n. We may write a = \Jve %B , where v = \ct\ 2 
denotes the mean photon number and e l6 is the phase of the coherent state. To an eaves- 
dropper with no a priori knowledge of the phase, a signal whose phase is selected uniformly 
at random is indistinguishable from the state 



a Poisson distributed mixture of photon number eigenstates. Therefore, for a security analysis, 
we may suppose that a source emitting weak coherent state signals is actually emitting signals 
in the state p v . 

With probability po — e _l/ , which is close to one for small v, the source emits no photon; 
exactly one photon is emitted with probability p\ — ve~ v . The probability that two or more 
photons are emitted is 



Multi-photons can pose a security risk, but if each signal has a random phase, pm is sufficiently 
small, and the loss in the channel is not too high, then it is possible to prove security of the 
Bennett-Brassard (BB84) protocol [1] against arbitrary eavesdropping attacks [12l [13] . 

However, no previously known security proof applies if the eavesdropper has some a priori 
knowledge about the phase of the signal states. Conceivably, such phase information might 
be accessible in realistic implementations of QKD. For example, in a "plug-and-play" scheme 
|17j . a strong signal is sent from Bob to Alice, who attenuates and modulates the signal before 
returning it to Bob; in unidirectional schemes as well, strong ancillary pulses are sometimes 
used to monitor the channel. The phase of a strong pulse is accurately measurable in principle, 
and could be correlated with the phase of the key-generating pulse. Furthermore, the key 
information itself might be encoded in the relative phase of a bright reference pulse and a weak 
signal pulse, in which case the eavesdropper could plausibly learn the phase of the reference 




(1) 





PM = 1 - e~ v (1 + v)) < -v 2 . 



(3) 
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pulse. Even if strong pulses are not used, the phase coherence of a realistic source might be 
maintained during the emission of many weak signals, allowing the phase to be determined 
accurately. 

For all these reasons, it is worthwhile to investigate the security of QKD under the as- 
sumption that the eavesdropper knows something about the phase of the signals. Our main 
result in this paper is a proof of security for the BB84 protocol in the case where the key 
information is encoded in the relative phase of a reference pulse and a signal pulse. Our 
proof works even if the reference pulse is bright, with a phase known by the eavesdropper. 
It also applies if the key is encoded in the photon polarization of weak coherent states with 
nonrandom phases, provided the phases of the signal states are chosen appropriately. The 
proof is founded on the observation that, if the signal pulse is weak, Alice's source reveals 
relatively little information to Eve about the basis that Alice uses to encode her key bits. 
Privacy of the final key is demonstrated using an argument due to Koashi [THl [19] that in- 
vokes the uncertainty principle. We also point out that this argument establishes that the 
key distribution protocol is universally composable — the key can be used in any subsequent 
application without compromising security. 

We describe our quasi-realistic model for sources and detectors in Sec. [U and present 
the security analysis (which relies heavily on Koashi's ideas [TBI US]) m Sec. [31 Sec. [H and 
Appendix A. In Sec.[5]we note that the key generation rate when the signals have nonrandom 
phases is comparable to the rate for phase randomized signals (when decoy states are not 
used). In Sec. [6] and Appendix B we point out that if the key is encoded in the photon 
polarization, and the (nonrandom) phases of the signals are not chosen judiciously, then 
BB84 is vulnerable to an unambiguous key discrimination attack, a measurement that, when 
conclusive, determines the key bit with certainty. Sec. [7] contains our conclusions. 

2 Modeling sources and detectors 
2.1 The source 

In the ideal BB84 protocol [TJ, each signal is carried by a single qubit sent by Alice and 
received by Bob. The qubit encodes a key bit in one of two conjugate orthonormal bases, 
which we will call the x basis and the y basis. When Alice uses the x basis, her signal states 
are 




(|0z) + |lz))/V2, 
(|0 z )-|l z »A/2, 



(4) 



the eigenstates with eigenvalues ±1 of the Pauli operator 




(5) 



when Alice uses the y basis, her signal states are 



|0y) 
|iy> 



{\0z)+i\lz))/V2 , 
(|0z)-i|l z »/V2, 



(6) 
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the eigenstates with eigenvalues ±1 of the Pauli operator 

' = (:»')■ m 

Alice's source emits one of these four states, chosen equiprobably. Bob measures the qubit 
that he receives in either the x basis or the y basis, chosen equiprobably, to determine his key 
bit. Later, through public discussion, Alice and Bob "sift" their key by retaining only the 
key bits for which Bob measured in the same basis that Alice used. The final key is extracted 
from the sifted key via a classical protocol that reconciles Alice's key with Bob's and amplifies 
the privacy of the key. 

In practice, the key information is carried by dim laser pulses transmitted through an 
optical fiber. In the protocol we will analyze, Alice's source emits one of four states of a pair 
of photon modes (described by annihilation operators aji and as)' 




(8) 

Here the phase of a is defined relative to a fixed classical phase reference frame that Eve can 
access. We will refer to the state of mode S as the "signal" pulse and to the state of mode 
R as the "reference" pulse. The key is encoded in the relative phase of the two pulses, and 
it is actually quite important for our analysis that the phase of the reference pulse is the 
same in all four of the signal states — only the phase of the signal pulse is modulated by the 
source. (We will discuss in Sec. [6] and Appendix [B] how security can be compromised when 
the phase of the reference pulse is also modulated.) In some implementations, the two pulses 
are spatially separated in the optical fiber by a distance large compared to the pulse width; 
this scheme is called "phase encoding." In some implementations, the two modes represent 
the polarization states of the same spatial mode; this scheme is called polarization encoding. 
Phase encoding has been used in most fiber-based QKD experiments. Our security analysis 
will also apply to phase encoding in the case where the reference pulse is brighter than the 
signal pulse. We will return to this generalization in Sec. IH but for now we will stick with the 
signals eq. ([8|), which could arise in either a phase-encoding or polarization-encoding scheme. 

To summarize, the crucial features of our source model are: (1) the single-mode signal 
pulse assumption (the signal pulse is carried by a single bosonic mode, the same mode for all 
four of the signal states), and (2) the unmodulated reference pulse assumption (the state of the 
reference pulse is the same for all four signal states). These assumptions are reasonably well 
fulfilled by realistic sources used for the BB84 protocol with phase-encoded signals. Previous 
proofs of the security of BB84 have used (2') the phase-randomization assumption (the phase 
of the reference pulse, but not of course the relative phase of signal and reference pulse 
that encodes the key information, is chosen uniformly at random and is not known by the 
eavesdropper). Our main new contribution in this paper is to prove security of BB84 using 
assumption (2) instead of assumption (2'). 
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2.2 The detectors 

When Bob wants to measure the signal he receives in the x basis, he (in effect) combines the 
two modes in an interferometer, and directs modes ao,x, o-i,x to two different "threshold" 
photon detectors, where 

aa,x = (a-R + a s ) /V2 , 

ai,X = (a R -a s )/V2. (9) 

Therefore, if Alice sends \0x) an d the ideal (unattenuated) signal enters Bob's measurement 
device (which is configured for x measurement), then detector receives a coherent state with 
mean photon number 

M = 2M 2 (10) 

and detector 1 receives the vacuum state. Likewise, if Alice sends then detector 

receives the vacuum, and detector 1 receives the coherent state with mean photon number \i. 
When Bob wants to measure in the y basis, the modes directed to the photon detectors are 

ao.Y = (a R + ia s )/V2, 

ai.y = (an -ias) /V% ; (11) 

again, depending on the key bit, one mode receives mean photon number fi while the other 
receives vacuum. 

We assume that each detector used by Bob to measure the signal he receives is a "thresh- 
old" photon detector. This means that the detector cannot distinguish a single photon from 
many photons. An ideal threshold detector "clicks" (registers a count) if it collects one or 
more photons, and does not click if it receives no photon; thus it performs a POVM with the 
two outcomes 

E ao dick = | vac) (vac | , 

£ciick =1- |vac)(vac| . (12) 

But in this paper we consider a threshold detector that is not ideal: we allow the detector 
to have imperfect efficiency (it sometimes fails to click even when it receives one or more 
photons) and to record occasional "dark counts" (it sometimes clicks even when it receives 
the vacuum state). 

Because Bob uses two threshold detectors, there are four possible outcomes when he 
measures a signal. If neither detector clicks, then the measurement is inconclusive and the 
signal is rejected. If detector b £ {0, 1} clicks and the other detector does not, then Bob 
records the key bit b. If both detectors click, then Bob records a key bit that he chooses 
uniformly at random. As noted in [12j and as we will explain below, it is important for 
the security analysis that double clicks are interpreted as key bits rather than regarded as 
inconclusive measurements. Actually, the security proof works the same way no matter how 
we map the double click events to key bits, but recording a random key bit is a particularly 
symmetric and natural choice. Given any fixed prescription for mapping double clicks to 
key bits, Bob's measurement realizes a POVM with three outcomes: 0, 1, and (when neither 
detector clicks) inconclusive. 
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Thus the protocol prescribes that Bob perform one of two possible POVMs, depending 
on whether Bob declares the x basis or the y basis, where each POVM has three outcomes. 
In fact, for our security proof we will not need to specify Bob's measurement in detail. All 
we require is that the measurement satisfy one assumption: Bob's three-outcome POVM is 
equivalent to a (basis-dependent) two-outcome POVM that determines the key bit, preceded 
by a basis-independent "filter" that allows the signal to pass if and only if Bob's measurement 
conclusively determines the key bit. 

Following Koashi |19j . we note that this property, that the inconclusive measurement 
outcome can be attributed to a basis-independent filter, follows if we adopt a particular well- 
motivated model of dark counts and detector inefficiency, and if we suppose that both of Bob's 
detectors have the same efficiency. First we note that the inconclusive outcome can occur only 
if neither detector has a dark count. Let us model the dark counts as a random background 
process, where the rate of background counts is an intrinsic property of the detector, not 
dependent on the state of the mode that is being measured. That is, a background click 
occurs in detector with probability do, whether mode ao,x or mode a^y is being measured, 
and in detector 1 with probability d\, whether mode a±^x or mode a\ t y is being measured. 
Thus, each time a signal is received, the probability (1— do){\— di) that there is no background 
click in either detector does not depend on whether Bob declares the x basis or the y basis. 

Furthermore, let us also assume |20j that when mode a$ t x (or ao,y) contains n photons 
the probability that detector fails to click is 

Prob(n photons, no click) = (1 - £)" , (13) 

where £ is the detector's efficiency, and similarly for detector 1. We may imagine that the 
detector induces decoherence in the photon number measurement before measuring — the 
real detector might not actually destroy the coherence of a superposition of states with two 
different nonzero photon numbers, but we are entitled to suppose that it does, because if so 
Eve's information and the measurement outcome would not be affected. Thus, each signal 
Bob receives can be regarded as a mixture of eigenstates of the total photon number n, where 
to < n of the photons are directed to detector and the remaining n — to photons are directed 
to mode 1. But if both detectors have the same efficiency £, and if the probability of no click 
is given by eq. (fT3| . then the probability that neither detector clicks depends only on n, not 
on to, and therefore it makes no difference whether Bob's detectors receive modes ao,x and 
ax,x ° r a o,Y and ax,Y\ i n other words the probability of an inconclusive outcome does not 
depend on whether Bob measures in the x basis or the y basis. 

We conclude, then, that when Bob receives an n photon signal, the probability that no 
click occurs in either detector, so that the measurement is inconclusive, is 

Prob(n, inconclusive) = (1 - d )(l - - £)" , (14) 

which does not depend on whether Bob declares the x basis or the y basis. Thus, we can 
imagine that a basis-independent filter is applied that measures the total photon number n 
and blocks the signal with probability Prob(n, inconclusive); if the signal passes the filter, Bob 
then performs a two-outcome POVM, either M x or M y depending on whether Bob declares 
the x basis or the y basis. 
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In order to describe Bob's measurement this way, we need a prescription for mapping 
the double click events to key bits. This prescription is needed because the probability of a 
double click event might depend on Bob's declared basis; therefore if the double clicks were 
regarded as inconclusive we would not be able to attribute the inconclusive outcome to a basis- 
independent filter. The prescription is incorporated into the definition of the measurements 
M x and M y , and for the security proof, the details of this prescription do not matter. 

We note that if Bob receives a coherent state with mean photon number fi, then the 
inconclusive outcome occurs with probability 

00 u n 

Prob(/i, inconclusive) = — -Prob(n, inconclusive) 

n=o n ' 

= (l-do)(l-di)e-*". (15) 

In particular, eq. JT5]) applies if Bob receives one of the signal states in eq. © and performs 
the measurement specified in eq. ([§]) or eq. (fTTj) , where fi — 2\a\ 2 . In that case, when Alice 
and Bob use the same basis, double clicks occur only because of dark counts, and when the 
measurement is conclusive and there are no dark counts Bob's key bit always agrees with 
Alice's. Attenuation in the channel reduces the probability of a conclusive outcome, but does 
not cause bit errors if the signals are otherwise unmodified and if Bob's measurement is ideal. 

To summarize, the crucial feature of our detector model is the basis-independent filter 
assumption, which says that Bob's measurement can be modeled by a basis-independent filter 
that removes all the signals for which the measurement of the key bit is inconclusive, followed 
by a (basis-dependent) two-outcome POVM that always produces a conclusive result. This 
assumption is reasonably fulfilled by realistic measurement devices used in BB84 provided 
that (1) Bob uses two threshold detectors with the same efficiency, (2) the probability that 
the detector fails to click decays exponentially as a function of the number of photons received 
(as in the standard theory of photodetection) , and (3) a prescription (either deterministic or 
probabilistic) is adopted for mapping double click events to key bits. We note that attacks 
have been proposed and analyzed [211 E2] that exploit a mismatch in the efficiency of Bob's 
two photon detectors, highlighting the importance of assumption (1). 

The basis-independent filter assumption limits Eve's ability to enhance her information 
about the signals by taking advantage of detector inefficiency. But we emphasize that our 
model still incorporates quite general flaws in the detection system (including for example a 
reduction in visibility due to an imperfect alignment of Bob's interferometer), because the 
POVMs M x and M y are arbitrary. Security is not compromised even if the detectors are very 
noisy, because in that case the bit error rate will be high and the key will almost certainly be 
rejected. 

3 Security analysis 

3.1 The unbalanced quantum coin 

We can analyze the security of this protocol by applying the methods of [T21 HH], where 
security was proven for the case where Alice's source emits signals that, averaged over the 
key bits, have a small dependence on the basis. To apply this method, we must quantify the 
basis-dependence of the signal set eq. (JSJ . 
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It is convenient to imagine that Alice launches each signal by performing a perfect mea- 
surement on a qubit that is entangled with the signal mode (the reference mode is always 
prepared in the state |a) no matter which signal is being sent). When Alice wants to send 
one of the two signals {|0x), |lx)}, we choose the entangled state of her qubit and the signal 
mode to be 

I**} = (|0x) ® \a) + |lx) ® | - a)) /V2 , (16) 

and we instruct Alice to determine her key bit by measuring her qubit in the basis {|0x), |lx)}- 
When Alice wants to send one of the two signals {|0y), |ly)}, we choose the entangled state 
of her qubit and the mode to be 

= (|ly) <8> \ia) + |0y) <g> | - ia)) /V2 , (17) 

and we instruct Alice to determine her key bit by measuring her qubit in the basis {|ly), |0y)}. 
See Fig. [TJ 

Now we notice that the states \^ x ) and \^f y ) are hard to distinguish when a is small. 
Using 

(ia\a) = e'^e'^ 2 = (-ia\-a) , 

{-ia\a) = e- |a|2 e l|Q|2 = (ia\-a) , (18) 

we find 

= e"l Q l 2 (cos|a| 2 + sin|a| 2 ) 
= e^ /2 (cos(/V2) + sin(/i/2)) 

= l- M 2 /4 + 0(/i 3 ) ■ (19) 

Note that there is no term linear in /i = 2\a\ 2 - that is, if we ignore the multi-photon 
contribution, the two states are indistinguishable. This happens because, to linear order in 
a, the two-dimensional subspace spanned by the two x-basis signals and the two-dimensional 
subspace spanned by the y-basis signals coincide. The large overlap of \ty x } and \^ y ) indicates 
that, averaged over the value of the key bit, the states emitted by the source when the x basis 
is chosen are hard to distinguish from the states emitted when the y basis is chosen. (We 
have chosen the purifications |^ x ) and \^y) that have the maximal overlap compatible with 
the key-averaged signal states |23j ; that is why we have paired |ly) with \ia) and |0y) with 
| - ia) in eq. pT|) .) 

A protocol such that the signals emitted by the source, averaged over the key bit, have a 
small dependence on Alice's basis choice can be analyzed by considering an equivalent protocol 
in which the basis-dependence of the signals can be related to the "balance" of a "quantum 
coin" [13l [18]. In this equivalent protocol, Alice measures the coin in the basis {|0z), \^z)} to 
determine whether her signal is encoded in the x basis or the y basis, and we may take the 
joint state of the coin and Alice's source states to be 

|$) = (\0z) <8 |* a ) + \lz) <8> |#„» /\/2 ; (20) 

furthermore we may imagine that the measurement of the coin is delayed until after Eve is 
finished interacting with the signals. 
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Fig. 1. Roles of Alice, Bob, and Eve in the key distribution protocol. Alice determines her key 
bit by performing an ideal measurement on a qubit that is entangled with the signal mode, (a) 
If Alice declares the x basis, then Alice measures in the x basis and the entangled state of her 
qubit and the mode is l^). (b) If she declares the y basis, she measures in the y basis and the 
entangled state is Bob's detector applies a basis-independent filter that determines whether 

his measurement has a conclusive outcome, followed by a two-outcome POVM, either M x or M v 
depending on Bob's declared basis. If Alice and Bob both declare the x basis, the probability that 
their measurement outcomes disagree is S x , and if both declare the y basis, the probability that 
they disagree is S y . 



If \^ x ) and \i$y) were equal, then the signals, averaged over the two possible values of 
the key bit, would be independent of whether Alice chose the x basis or the y basis. If \^> x ) 
and \tyy) are nearly equal, then the source leaks a small amount of information about Alice's 
basis choice that Eve might exploit. A useful way to quantify the leaked basis information 
is to consider what would happen if Alice were to measure each of her coins in the basis of 
X eigenstates rather than the basis of Z eigenstates; then the outcome X = — 1 would occur 
with probability A, where 

= 1-2A . (21) 

Thus we say that the coin is "A-balanced," where A quantifies the basis dependence of Alice's 
signals. For the signal states eq. ([8]), we have 

A = i(l- e -^ 2 (cos( M /2) + sinW2))) 

= n 2 /8 + 0(fi 3 ) . (22) 

However, not all of the signals emitted by the source are detected; Eve, by carefully 
choosing which signals to block, might be able to enhance the basis dependence of the detected 
signals. Let us pessimistically assume that the detected signals are chosen to maximize the 
imbalance of the coin. For a perfect channel and for perfect detection efficiency, the fraction 
of signals detected would be 1 — e _A1 w jj,, where /i is the mean photon number of the signals 
emitted by the source. The actual fraction of detected signals is rjn, where 77 is an effective 
rate of loss due to absorption in the channel and imperfect detector performance. In the worst 
case, for all of the signals that are removed, the coin is an X — 1 eigenstate, which would 
enhance the probability of the outcome X = — 1 by 

A -> A' = A/( W ) a fi/(8r)) . (23) 

Thus we will use A' to quantify the basis dependence in the signals that determine Alice's 
sifted key. 
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We will argue that for a fixed A' that is sufficiently small, secure key can be extracted 
from sifted key at a fixed nonzero asymptotic rate. Therefore, the number of private key bits 
that can be generated per transmitted signal is proportional to « 8A'7y 2 and hence scales 
like r/ 2 — the same scaling as for a source with random phases [12l E] (assuming that decoy 
states are not used). 

3.2 The uncertainty principle and privacy amplification 

Koashi [18] , generalizing the techniques in [13] , explained how to relate the imbalance of the 
quantum coin to the privacy of a key that is generated by performing ideal measurements on 
qubits; here we wish to apply his reasoning to Alice's key bits, which we regard as determined 
by outcomes of measurements of (fictitious) qubits entangled with the signal states. For 
our argument, it is important that the imbalance of the coin arises solely from the basis 
dependence of Alice's signals. That is why we required that Bob's measurement be modeled 
by a basis-independent filter followed by a two-outcome measurement; if the probability of an 
inconclusive outcome actually depended on the basis, then the basis-dependence of the filter 
might have further enhanced the imbalance of the coins. As it is, after the inconclusive 
measurement results arc discarded, we may imagine that Bob performs his two-outcome 
POVM on signals that are entangled with Alice's qubits and the quantum coins, where the 
imbalance A' of the coins is determined only by the basis dependence of the source and the 
loss in the channel. 

We recall that the BB84 protocol includes a verification test conducted by Alice and Bob. 
In the test, Alice and Bob publicly compare a randomly selected subset of their key bits 
to estimate a bit error rate, the fraction of the key bits for which Alice and Bob disagree. 
Signals sent in the x basis and the y basis can be tested separately, to estimate both a bit 
error rate S x for signals sent in the x basis, and a bit error rate 6 V for signals sent in the y 
basis. Let us consider the key bits that are generated by measuring in the x basis. Using 
Koashi's method [18] . we may show that, in the asymptotic limit of a very long key, private 
key can be extracted from Alice's sifted key at a rate 

R = 1 - H(6 X ) - H(6' y ) , (24) 

where 5 X is the bit error rate, S' y > S y is a function of 5 y and A', and H{$) = — S\og 2 S — 
(1 — S) log 2 (l — d) is the binary Shannon entropy. A similar formula applies for the key bits 
generated by measuring in the y basis, but with 5 X and 8 y interchanged. The term H(S X ) 
is the rate at which sifted key must be sacrificed to perform error correction that reconciles 
Bob's key with Alice's (according to standard Shannon theory), and H{5' y ) is the cost of 
performing privacy amplification to ensure that Eve has negligible information about Alice's 
final key. 

What is the quantity 8' y l Recall that when the x basis is declared, Alice measures her 
qubit in the x basis and Bob performs measurement M x , while if the y basis is declared, 
Alice measures her qubit in the y basis and Bob performs measurement M y . Furthermore, 
when the x basis is declared, the entangled state of Alice's qubit and the signal mode is \^ x ), 
while when the y basis is declared, the entangled state is \^ y ). The quantity S' y is an upper 
bound on what the bit error rate would have been if Alice measured in the y basis and Bob 
performed measurement M y , but where the entangled state of the qubit and mode is \^ x ) 
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Fig. 2. Setting that defines the "phase error rate" 8' y . The entangled state of Alice's qubit and the 
signal mode is \^x) as though Alice had declared the x basis, but Alice and Bob both measure in 
the "wrong" basis — Alice measures y instead of x, and Bob measures M y instead of M x . The 
probability that Bob's outcome disagrees with Alice's is 5' y . The quantity S' y cannot be directly 
measured in the protocol, but an upper bound can be inferred from the observed bit error rate 8 y 
and the known basis dependence of Alice's signal states. 

instead of \^ y ). This hypothetical error rate is not known directly from the test, but because 
the state \^ x ) is close to \^> y ) when A is small, the hypothetical "phase error rate" S' y is close 
to the actual observed bit error rate S y . See Fig. [2l 

The estimate of 6' is explained in Appendix [TJ The result is that for any e > 0, with high 
probability we may express S' y as 

5'y = S y + 4A'(1 - A')(l - 2S y ) + 4(1 - 2A')^/A'(1 - A')5„(l -<*„)+£ 

< S y + 4A' + 4^/A% + e . (25) 

The upper bound on S' y in the last line is obtained by retaining only the terms of lowest order 
in S y and A', and gives a reasonable approximation to the tighter bound on the previous line. 
From the tighter bound and eq. (|24|) . we see that the key generation rate R remains positive, 
in the limit of negligible bit error rates S x , S y , for A' < 0.146, which corresponds to fi smaller 
than about (1.16)77 when 77 is small. 

Why does S' y characterize the cost of amplifying privacy? Following Koashi [TS] (and 
generalizing an idea used in [5] and [3]) we observe that when the x basis is declared, Eve's 
knowledge about Alice's key would not have been affected if Bob had chosen to measure in 
the wrong basis (to measure M y rather than M x ). Furthermore, neither the key nor Eve's 
knowledge of the key would have been affected if Alice had chosen to delay measuring her 
qubits until after Bob measured the signals that he received. Therefore, we may imagine that 
Alice generated her key by measuring in the x basis a string of qubits that, conditioned on 
the outcome of Bob's M y measurement, are close to y-basis eigenstates (if S' y is small). 

If, after Bob's measurement, each of Alice's qubits were exactly a y-basis eigenstate, then 
Eve would be powerless to predict the key bits that Alice obtains by measuring the qubits in 
the x basis. In that case we could say that the privacy of the key is founded on the uncertainty 
principle: a qubit that produces a deterministic outcome when measured in the y basis will 
produce a uniformly random outcome when measured in the x basis. From this perspective, 
we may say that the purpose of the privacy amplification is to ensure that Alice's final key is 
very nearly equivalent to a key determined by measuring y-basis eigenstates in the x basis. 
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Let the n-component binary vector v denote Alice's sifted key for the signals in which the 
x basis was declared by Alice and Bob, and Bob reported successfully detecting the signal. 
Alice extracts her fc-bit final key k = vG by applying the random rank-A: binary n x k matrix 
G to the sifted key. Equivalently, we may say that Alice's final key is obtained by measuring 
the k binary observables 

*i= (8) X i ■■ * = 1,2,3,...*, (26) 

where Xj denotes the Pauli matrix X acting on Alice's jth qubit. 

Before selecting the matrix G, we might have first selected a random rank-(n — k) binary 
n x (n — k) matrix H , and then chosen G subject to the constraint G T H = (so that each 
column of G is orthogonal in the binary inner product to each column of H). In that case, 
each of the n — k binary observables 

Y m = (g) Yj , m= 1,2,3,... n-k (27) 

j:H Jm =l 

(where Yj denotes the Pauli matrix Y acting on Alice's jth qubit) would commute with each 
of the Xi's. We may therefore imagine (since it would have no effect on Alice's final key or 
on Eve's information about the key) that Alice measured each of the Y m 's before measuring 
the X^s to determine her final key bits. 

Now, if Alice were to measure all of her qubits in the y basis, then with probability 
exponentially close to 1 for n large, her outcome would be one of A^ typ = 2 n WH=) typical 
n-bit strings. Note that if u and v are two distinct n-bit strings, and s is a randomly chosen 
n-bit string, then the bits us T and vs T are distinct with probability 1/2. Therefore if we 
choose the number of randomly chosen binary observables in the set {i^n} (the number of 
columns in the matrix H) to be 

n-k= n(H(5' y ) + 2e) , (28) 

then the probability that more than one typical binary string is compatible with the outcomes 
of the {Y m } measurements is at most A r typ -2 fc "™ = 2~ £n . This means that, conditioned on the 
results of measuring all the observables in the set {i^}, Alice's n qubits have been projected 
to a state that is exponentially close to a product of y-basis eigenstates. Thus Alice's final 
key is essentially the same as it would have been if the sifted key had been generated by 
measuring y-basis eigenstates in the x basis, and therefore is guaranteed to be private. Since 
k = n(l — H(S' y ) — 2e), and n[H{8 x ) + e') key bits are sacrificed to reconcile Bob's sifted key 
with Alice's, we obtain the asymptotic key rate eq. (f24|) . 

3.3 Universal compos ability 

This argument shows not just that Eve's mutual information with the final key is negligible, 
but also that a stronger definition of security is satisfied: the protocol is universally compos- 
able [2H [23 [55] . This means that the final key bits can be safely used in any subsequent 
application without compromising security. To demonstrate composability, we consider in 
more depth (following [2B]) the joint state shared by Alice and Eve before Alice performs her 
x-basis measurements to generate her key. We have already seen that, after Alice's fictitious 
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measurement of the observables {l 7 ™,}, her density operator pa has high fidelity with the pure 
state | j/o) i where | j/o) denotes a particular product of y-basis eigenstates: 

F(p A , \y Q )(y Q \) = {y \ PA \yv) = 1 - C 2 , (29) 

where £ is exponentially small. Therefore we may introduce an auxiliary system E, which we 
pessimistically assume to be under the eavesdropper's control, such that pa has a purification 
\Y}ae where IT)^ has a large overlap with \yo)A <8 |A)_e and |A) b is a pure state of E: 

F{ (|T) (T\) AE , (\y )(yo\) A ® (|A)(A|) E ) = 1 - C 2 ■ (30) 
We can relate the large overlap to proximity in the trace norm, using the inequality 

±\\ P -cr\\ tI <y/l-F(p,cT) , (31) 

obtaining 

~ll (\?)(T\)ae ~ (\Vo){Vo\) A ® (|A)(A|) B || tr < C ■ (32) 

Now when Alice measures the observables {Xi} to determine her final key, the state \yo) (uo I 
yields a uniformly random key described by the maximally mixed density operator 

2 fe -l 

Pa 1 = 2* E l K >< K l ' ( 33 ) 

and the resulting state shared by Alice and Eve is a product state p A nl ® ag, where ge = 
(|A)(A|) £ . Quantum operations cannot increase the trace distance; therefore, if pae is the 
state shared by Alice and Eve after Alice's measurement, we find that 

\\Pae-pT®°e\V,<C, ■ (34) 

Eq. (|34p is a security criterion shown to be universally composable in [25] . which we have 
now seen is satisfied by a protocol where the signal states have nonrandom phases. This 
demonstration of universal composability for the BB84 quantum key distribution protocol 
also applies to the other cases addressed by Koashi in [18l [19] . 

4 Bright reference pulse 

Our security proof also applies if the reference pulse is bright. Suppose that, for each of the 
BB84 signals, the state of the reference pulse emitted by the source is \(3)r, while the emitted 
state of the signal pulse is as in eq. ©, where \j3\ > \a\. Then we may calculate the imbalance 
of the quantum coin as before, except in eq. (|22p we replace p/2 by ps = |ck| 2 , the mean photon 
number of the signal pulse. When Bob receives the signals, he first attenuates the reference 
pulse so that its strength matches the strength of the signal pulse, and then performs the 
interferometric measurement described earlier. Thus we replace rjp in eq. (|23p by 2r]ps, the 
mean total photon number of the two modes after the attenuation of the reference pulse (and 
taking loss into account). Therefore, in both formulas we replace p by 2p$, finding 



A' » ps/{^) , 



(35) 
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when the signal pulse is weak. It is obviously essential for this argument that the (possibly 
bright) reference pulse has exactly the same state (or at least very nearly the same state) for 
each of the BB84 signals, so that it conveys no information (or very little information) to Eve 
concerning which signal is emitted. Eve might tamper with Bob's measurement of the signal 
by attacking the reference pulse, but because she knows little about the basis in which the 
key bit is encoded, she is still incapable of collecting much information about the key without 
creating a detectable disturbance. 

Why is it that Eve seems to be no better off when the reference pulse is bright than when 
it is as dim as the signal pulse? The reason is that even when the reference pulse is dim we 
have pessimistically assumed that Eve knows the phase of the reference pulse perfectly. When 
we say that Eve "knows" that the state of the reference pulse is the coherent state \{3)r, we 
are taking it for granted that the phase of (3 has a fixed value relative to a classical phase 
reference that Eve controls. If the phase of (3 were not already known, then increasing \(3\ 
would make it easier for Eve to determine the phase relative to her reference frame, but if the 
phase is already known then increasing \(3\ does not give Eve any additional advantage. 

The observation that the reference pulse can be bright without compromising security is 
relevant to, for example, the "double Mach-Zehnder" scheme for implementing phase encoding 
[27l 128] . In this set-up, Alice uses an unbalanced interferometer to split a single pulse into 
two spatially separated pulses that travel to Bob through the same optical fiber; one of these 
pulses, whose phase is unmodulated, is the reference pulse, and the other, whose phase is 
modulated, is the signal pulse. Bob uses another unbalanced interferometer to combine the 
two pulses, with a modulated relative phase that determines his measurement basis. 

For a given strength of the signal pulse, using a brighter reference pulse increases the 
key rate by reducing the probability that Bob fails to detect the signal. In particular, if the 
reference pulse is much brighter than the signal pulse, then nearly twice as many signals will 
be detected compared to the case where the reference and signal pulses have equal strength. 
Our proof shows that the key rate can be doubled by using a bright reference pulse, without 
reducing the privacy of the final key. 

We can understand this doubling of the key rate by considering how Bob's detection system 
operates in the double Mach-Zehnder scheme. Let us suppose that the reference pulse follows 
the longer path in Alice's unbalanced interferometer and therefore lags behind the signal 
pulse during transmission through the fiber; we therefore use (L for "long") to denote the 
reference mode, and as (S for "short" as well as "signal") to denote the signal mode. The 
two paths in Bob's interferometer also have unequal lengths, to compensate for the spatial 
separation in the fiber of the reference and signal pulses: the portion of the reference pulse 
that follows the short path in Bob's interferometer (let us call it the LS mode, since it follows 
the long path in Alice's interferometer and the short path in Bob's) interferes with the portion 
of the signal pulse that follows the long path in Bob's interferometer (the SL mode). The first 
beam splitter in Bob's interferometer is asymmetric, so that the reference and signal pulses 
are split according to 

1/5} l -» \cP) LL ® \80) LS , 

\&)s i-» \ca)sh ® \sa)ss , (36) 
where c 2 + s 2 = 1. Here LL refers to the part of the reference pulse that enters the long arm 
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of Bob's interferometer, and SS refers to the part of the signal pulse that enters the short 
arm; these LL and SS modes are ignored by Bob. We denote the strengths of the reference 
and signal pulses by (3 and a rather than (3 and a to take into account the attenuation of the 
pulses during transmission through the fiber; thus, ifEvedoes not intervene, |a|/|/3| = |a|/|/3|. 

Bob's first beam splitter is chosen so that s\f3\ = c\a\, or s/c — \a\/\(3\; therefore the 
incoming LS and SL modes at Bob's second beam splitter have equal strength. This second 
beam splitter is symmetric, and Bob reads out his device by detecting the photons in the two 
output ports of this symmetric beam splitter. The probability of detection is proportional to 
the total mean photon number in the LS and SL modes as they arrive at Bob's second beam 
splitter, which is 

s 2 |£| 2 + c 2 |a| 2 = 2c 2 |a| 2 , (37) 

where 

c2= 1 _ Ifl 2 _ HI 2 (38) 

The factor c 2 suppressing the detection rate arises because the strength of the signal pulse 
following the long path in Bob's interferometer is attenuated by the factor c at the first beam 
splitter; the rest of the signal pulse follows the short path and is wasted. This factor c 2 is 1/2 
for \a\ = |/3 1 but close to 1 for |/3| 2 ^> \a\ 2 . Thus when the reference pulse and signal pulse 
have the same strength half of the signal is wasted, but when the reference pulse is bright 
hardly any of the signal is wasted. 

5 Comparison to phase-randomized signals 

It is instructive to compare our estimate of the key generation rate with the rate that would 
be achievable if the phases of the signals were random. In that case, the quantum coin 
is undisturbed if the source emits a single photon, but it is strongly affected if two or more 
photons are emitted. Thus the fraction of the coins that are damaged is at worse A' = Pm/pd, 
where pm is the probability for emission of a multi-photon, and po is the fraction of the signals 
that are detected. Therefore, for small ji we have [T3"] 



iu 2 

A' = Pm /pd~ — =»/2v ■ (39) 



The key generation rate again has the form eq. (|24|) . but for coins in this particular type of 
state (a fraction A' badly damaged and a fraction 1 — A' undisturbed), the estimate of 6' y 
can be improved to 

S' y -S y = A'/2 » M /4r? . (40) 

(Eq. (j40| is an improvement found in [29] of the result S' y — 5 y — A' found in [13].) For 
comparison, by combining eq. (|23| with eq. (|25| we find 



S^-SyMiifin + finSy/ri (41) 

for the case where Eve knows the phase of the signals; thus we see that phase randomization 
improves the rate, but only by a relatively modest amount when the bit error rate is small. 

In fact, as shown in [13] , for a phase-randomized source a higher key generation rate can 
be achieved than implied by eq. (I24[) and eq. (|40p . furthermore as shown in [19j this higher 
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Distance [km] 

Fig. 3. The key generation rate in bits per pulse as a function of distance for sources with random 
and nonrandom phases, using experimental parameters from |10 |. and assuming an error-correction 
inefficiency /(e) = 1.22. Here for the phase-randomized case we assume that decoy states are not 
used. For each value of the distance, the signal strength has been chosen to optimize the rate. 



rate applies for the detector model assumed in Sec. [2j The achievable number G of key bits 
per pulse can be expressed as 

G = \ (Qi (1 - H(ei)) - Qf(e)H(e)) . (42) 

Here Q is the fraction of pulses for which Bob detects the signal, e is the bit error rate observed 
in the verification test, and /(e) > 1 parametrizes the inefficiency of the error correction used 
to perform key reconciliation; furthermore e\ is the error rate for the single-photon signals 
emitted by the source and Q\ is the fraction of the single-photon signals that result in a 
detection event. (The factor of \ in front of the expression for G arises because half of the 
detected signals, those for which Alice and Bob used different bases, are discarded during 
sifting.) In a protocol that uses decoy states, Q\ and e\ can be estimated directly, but if 
decoy states are not used then we may pessimistically assume all the bit errors are due to 
single-photon signals, so that 

e x = e/(l - A') (43) 
(with A' = pm/Q), and that all the multi-photon signals are detected, so that 

Qi = Q(l - A') . (44) 
For the case of a source with nonrandom phases, the achievable key rate per pulse is 

G = ±Q(1 - f(e)H(e) - H(e ph )) ; (45) 
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here e p h as a function of e is given as in eq. (|25ll by 



e ph = e + 4A'(1 - A')(l - 2e) + 4(1 - 2A')a/A'(1 - A')e(l - e) 



(46) 



where 




(47) 



We have plotted the key rates per pulse given by eq. (|4"2"| and eq. (|4"5)) as a function of distance 
in Fig. [3J For this comparison, we have used experimental parameters (channel loss, dark 
count rate, and detector efficiency) from [10j . and assumed an error-correction inefficiency 
/(e) = 1.22; for each value of the distance, the signal strength /i has been chosen to optimize 
the rate. The maximal distance for which secure key exchange is possible is about three times 
longer in the phase-randomized case. 

6 Phase modulated reference pulse 

The security proof works because the overlap of \^ x ) and \^ y ) is 1 — O(jig). This property 
holds because, if we assume that the phase of the reference pulse is unmodulated, then the 
four BB84 signal states span a two-dimensional space when the multi-photons in the signal 
pulse are neglected. But, even when the reference pulse is weak, the story can change if 
the source modulates the phase of the reference pulse as well as the signal pulse. In [30] we 
studied such a source, and we concluded that the eavesdropper can exploit the modulation of 
the reference pulse to improve the effectiveness of her attack. 

In particular, in Appendix IBl (see also [331]), we study the BB84 signal states 



in which the reference pulse for each signal has a distinct phase relative to Eve's classical phase 
reference. Thus key information is encoded not just in the relative phase of the signal and 
reference pulses, but also in the phase of the (dim) reference pulse relative to Eve's reference 
frame. The signal set eq. (|48j) seems more natural if we recognize that, when re-expressed in 
a different basis, it becomes the signal set eq. (IB.1[) ; thus it arises in a polarization encoding 
scheme where the single-photon component of each signal is the standard BB84 single-qubit 
signal, and where the relative phase of the vacuum and single-photon component is the same 
for all four signals. 

We note that, even if we ignore the (small) multi-photon component of the weak coherent 
state signals, these four BB84 signals belong to a three-dimensional Hilbert space spanned by 
the vacuum (no-photon) state and two distinguishable one-photon states. On the other hand, 
the two signals that convey a particular key bit value (0 or 1) span a two-dimensional space. 
Therefore, an eavesdropper who knows the relative phase of the vacuum and single photon 
component can launch an attack on the protocol that we call unambiguous key discrimination. 
She performs a POVM with three outcomes: 0, 1, and inconclusive; if either of the conclusive 




(48) 
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outcomes occurs, then Eve knows with certainty the key bit (0 or 1) encoded in the BB84 
signal emitted by the source, though she does not gain any information about which of the 
two possible BB84 states compatible with that key bit was emitted. 

For these signal states, we show in Appendix [Bl that Eve's key discrimination has a con- 
clusive outcome with probability pc ~ when the mean photon number \x is small. If the 
signals had random phases, then only the multi-photon signals would be insecure, a fraction 
0(fj, 2 ) of all the signals. But when the phase of a is known and the signals eq. (|48|) are used, 
this fraction increases to O(fi). 

As van Enk [31] has astutely pointed out to us, the unambiguous key discrimination attack 
becomes much less effective if the encoding of the signals is chosen judiciously. And for the 
signal set eq. (|5J) in which the reference pulse has the same phase in all four signals, the signals 
span a two-dimensional space when the multi-photons are neglected, so that the conclusive 
key discrimination succeeds with probability pc — 0(p 2 ). (For polarization encoding, this 
corresponds to particular choices for the phases of the coherent states and for the orientation 
of the BB84 polarization states in the Bloch sphere.) Thus as we have seen, unconditional 
security is provable for this particular encoding, but the proof does not apply to the signal 
set eq. (j48|) . Therefore, the protocol is vulnerable to a "Trojan horse" attack, in which a 
malicious manufacturer in cahoots with Eve provides Alice with a source that modulates the 
phase of the reference pulse [32] • 

There are other possible Trojan horse attacks that could be even more devastating — for 
example the source might encode the four BB84 states in four distinct bosonic modes so that 
Eve can distinguish the signals perfectly. It is useful, however to differentiate such multi-mode 
Trojan horse attacks from the more subtle attacks where the protocol is compromised because 
the source modulates the phase of a single mode. The single-mode Trojan horse might be 
harder for Alice and Bob to detect, and might be less susceptible to countermeasures [33 a 
such as filtering out the unwanted modes. 

7 Conclusion 

In summary, we have shown that the BB84 quantum key distribution protocol with phase- 
encoded signals is secure if the signal pulse is weak. Our proof applies even if the reference 
pulse is bright and has a phase known by the adversary, provided that the phase of the 
reference pulse is the same for all four of the BB84 signals, and the measurement device 
satisfies the basis-independent filter assumption formulated in Sec. O Furthermore, our proof 
shows that the BB84 protocol is universally composable under these conditions. Our security 
proof also applies to polarization encoding, if the signal states are chosen appropriately. And 
we have discussed a new type of single-mode Trojan horse attack, in which security can be 
compromised because the source modulates the phase of the reference pulse depending on 
which signal is being emitted. 

The achievable key rate established by our proof scales quadratically with the transmission 
r\ in the channel, as for BB84 with phase-randomized weak coherent-state signals. In the 
phase-randomized case, a key rate linear in r\ can be achieved with the decoy state method. 
An interesting open question is whether employing decoy states can also extend the range over 
which secure BB84 quantum key distribution is possible in the case where the eavesdropper 
knows the phase of the (possibly bright) reference pulse and the detector is modeled as in 
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Sec. O We note that a key rate linear in r\ has been established for the B92 [27] protocol 
assuming that the reference pulse is bright and the detector has suitable properties (one proof 
requires Bob to have a local oscillator phase-locked with the reference pulse [34] . another 
requires that Bob's detector can distinguish single-photon signals from multi-photons [35]). 
but these proofs do not apply to the threshold detectors used in current experiments. It may 
also be fruitful to investigate the impact on security of using imperfect sources and detectors 
for other quantum key distribution protocols, such as the six-state protocol [36] and SARG04 

m- 

Finally we remark that, since a higher key generation rate has been established for the 
case where the reference pulse has a random phase than for the case where the phase is known, 
it may be advantageous to deliberately randomize the phases of the signals in order to reduce 
the eavesdropper's power. An experimental demonstration of quantum key distribution using 
active phase randomization was recently reported in [38] . 
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Appendix A Bounding the phase error rate 

The argument in Sec. [3] invokes the uncertainty principle to establish that private key can 
be extracted from sifted key at the asymptotic rate R shown in eq. (|24]k this rate depends on 
an observed bit error rate 8 X and an unobserved "phase error rate" S' y for the signals sent in 
the x basis. In this Appendix, we derive eq. (|25p , which expresses S' y in terms of the observed 
y-basis bit error rate S y and the imbalance A' of the quantum coin that determines the basis 
choice. The derivation is nearly identical to an argument used by Koashi in [18) : we include 
it in this paper so that our security analysis will be self-contained. 

The derivation uses the "Bloch sphere bound" proved in [39j . Note that for an arbitrary 
state of a single qubit, expectation values of the Pauli operators X and Z obey the inequality 

(X) 2 + (Z) 2 <1; (A.l) 

the polarization vector in the qubit lies within the Bloch sphere of unit radius. The Bloch 
sphere bound asserts that a similar inequality applies with high probability if (X) and (Z) 
are estimated by randomly sampling from a correlated state of many qubits. That is, consider 
an arbitrary state of 2n qubits, and randomly select a subset of n qubits. Measure in the x 
basis each of the n qubits in the subset, and let n"/ x denote the number of those qubits for 
which the outcome of the measurement is X = —1. Then measure the rest of the qubits in 
the z basis, and let wj z denote the number of qubits for which the outcome is Z = —1. Then 
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for any e > and with probability exponentially (in n) close to 1, 

(1 - 2 7x ) 2 + (1 - 2 7z ) 2 < 1 + e . (A.2) 

Thus, despite the possible correlations among the qubits, the results are constrained by the 
naive Bloch sphere bound in the limit of large n. It is convenient to rewrite this inequality 
(suppressing the e) as 



1 - 2 7x < 2^7,(1-7,) . (A.3) 

We could apply the Bloch sphere bound to the quantum coin; the coin is measured in 
the z basis to determine whether Alice will encode her key bit in the x basis or the y basis. 
Thus -f z is the probability that Alice declares the y basis, 1 — 7 Z is the probability that Alice 
declares the x basis, and the "imbalance" of the coin is A' = 7a; . 

However, our goal is to relate the bit error rate S y that is observed when the y basis is 
declared to the bit error rate S' y that would have been observed when the x basis is declared, if 
both Alice and Bob had measured in the "wrong" basis (the y basis rather than the x basis). 
Therefore, we will imagine that Alice and Bob always measure in the y basis, and we will 
divide the signals into two sets — the set for which Alice and Bob find key bits that agree 
(the set "n" for "no error") and the set for which Alice and Bob disagree (the set "e" for 
"error" ) . 

Let X co i n denote the Pauli operator X acting on the coin, let Z com denote the Pauli 
operator Z acting on the coin, and define 

7^) - Prob(X coin = -l\Y error) , 
7 < e ) = Prob(Z coin = -1 | Y error) , 
~/i n) = Prob(X coin = -1 | no Y error) , 

7 ( n) = Prob(Z coin = -1 | no Y error) . (A.4) 
Applying the Bloch sphere bound to the signals with a y-basis error we obtain 

l-2 7 ( e >< 2^(1-7^), (A.5) 
and applying it to the signals with no y-basis error we obtain 

l-27(" ) <2V / 7i" ) (l-7i" ) ). (A.6) 

Using Bayes's rule, we have 

Prob(Z coin = -l,y error) 

= Prob(Z coin = -1) • Prob(F error | Z coin = -1) 

= lz5y 

= Prob(Z co j n = — 1 | Y error) • Prob(F error) 

= 7^ • Prob(F error) , (A.7) 
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and likewise 

Prob(Z coin = 1,Y error) 

= Prob(Z coin = 1) • Prob(F error | Z coin = 1) 

= (i-7,)*; 

= Prob(Z co ; n = 1 | Y error) • Prob(Y error) 

= (1 - 7< e) ) • Prob(F error) . (A.8) 

Furthermore, 

Prob(X coin = -1,Y error) 

= Prob(X co j n = — 1 | Y error) • Prob(Y error) 

= ^ ■ Prob(F error) ; (A.9) 

therefore, multiplying both sides of eq. (|A.5j) by Prob(F error), we find 

Prob(Y error) — 2 Prob(A co i n = — 1, Y error) 
<2^ lz (l- lz )5 y 5' y . (A.10) 

By applying the same reasoning to the signals with no y-basis error, we find from eq. (|A.6|) 
that 

Prob(no Y error) — 2 Prob(A co ; n = — 1, no Y error) 

< 2^(1 - 72 )(1-(S„)(1-^) . (All) 

Now adding together eq. (|A.10p and eq. (|A.11|) . we have 

1 - 2A' = 1 - 2 Prob(Jf coin = -1) 

< 2 v / 7 ,(i- 7z )( v /v; + . v /(i- ( 5,)(i-^) ) 

< y/s^+y/(l-S y )(l-S' y ) . (A.12) 

This inequality says that S' y must be close to S y if A' is small. After some algebra (and after 
reinstating e), we may re-express eq. (|A.12|) in the form eq. (|25l) . 

In our analysis, we have allowed a basis asymmetry in the detected signals (% ^ 1/2)- 
This asymmetry might occur because the source leaks a small amount of information about 
the basis choice, and Eve could use that basis information to (say) block more x-basis signals 
than y-basis signals. However, using the available basis information to enhance the basis 
asymmetry is not a good strategy for Eve. Rather, her attack is most effective when S' y — S y 
is largest, and eq. (|A.12j) indicates that the maximal possible value of S' y — S y occurs when 
x-basis and y-basis signals are detected with equal likelihood (7, = 1/2). 

In the end, the inequality eq. (|A.12[) has a simple form and in fact it admits a simple 
interpretation. Recall that if p x and p y are two density operators and the operators {E a } are 
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the elements of a POVM, then there is an inequality relating the fidelity of the two density 
operators to the statistical overlap of the measurement outcomes: 

^F(p x , Py ) = ||VA^/ftdV ^ \J ^{PxEa)tT(pyE a ) . (A.13) 

a 

Ignore for the moment the correlations among the signal states that might be induced by 
Eve's attack, and suppose that, for each signal, the joint state of the qubit measured by Alice 
and of the bosonic modes measured by Bob is p x when Alice declares the x basis and p y 
when Alice declares the y basis. Recall that for the detector model formulated in Sec. [2J 
the probability that Bob's measurement yields a conclusive outcome does not depend on 
whether Bob measures in the x basis or the y basis; let us denote this probability that Bob's 
measurement is conclusive as Q x in the state p x and Q y in the state p y . Let {E a } be the three- 
outcome POVM that outputs "inconclusive" when Bob's measurement is inconclusive, outputs 
"agree" when Bob's y measurement is conclusive and agrees with Alice's y measurement, and 
outputs "disagree" when Bob's y measurement is conclusive and disagrees with Alice's y 
measurement. Then eq. (|A.13I) becomes 

^F( Px ,p y ) < ^(l-Q x )(l-Qy) + V^y(^y + \/( l -W-K)) ■ ( A - 14 ) 

For a fixed value of Q x + Q y , the right-hand side of eq. (|A.14[) is maximized for Q x = Q y ; 
therefore, defining Q — (Q x + Q y )/2, we find 

^F( Px , Py ) < 1-Q + q( v /^+ v /(1- ( J !/ )(1-^)) . (A.15) 

But Eve's attack cannot improve the distinguishability of p x and p y ; thus 

1 ~ 2A = \(* y \* x )\ < ^F( Px , Py ) , (A.16) 

and so we obtain 

1 - 2A' < ^SyJ y + J(i-6 y )(l-6' y ) (A.17) 

where A' = A/Q, in agreement with eq. (|A.12j) . 

This fidelity argument establishes security against individual attacks, but we have not seen 
how to turn it into a rigorous proof of security against collective attacks. Recall that we need 
eq. (|A.12jl to hold with high probability even if (after Eve's attack) the signals are highly 
correlated with one another. For this purpose it would be natural to use the quantum de 
Finetti theorem [401 EI] to show that the state of all the signals can be well approximated by 
a convex combination of product states. But unfortunately, because the Hilbert space of the 
signal and reference modes is infinite dimensional, the de Finetti theorem does not provide 
a useful approximation. Fortunately, though, the argument based on the imbalance of a 
quantum coin applies for any two-outcome POVM that Bob might apply (after the filtering), 
irrespective of the dimension of Bob's Hilbert space. 
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Appendix B Unambiguous key discrimination 

In this Appendix, we elaborate on the unambiguous key discrimination attack against the 
signal set eq. (j48|) . It is convenient to express the signals in an alternative basis, which is 
natural from the perspective of polarization encoding: 



|0z) = e-»l' 2 (Jvac) + V2 a\0 z ) + . 

\lz) = e^ /2 (|vac) + V2a|l z )+. 

\0 X ) = e^ 2 (jvac) + V2 a|0 x ) + ■ 

\1 X ) = e-^ 2 (|vac) + ^a|l x ) + ...) ; (B.l) 



here {|0z), \lz), \0x), |lx)} are the ideal BB84 states encoded in the polarization of a single 
photon, and the ellipsis indicates the multi-photon contribution. In this basis, the phase of 
each signal is e l9 = 1, so that a — yfJi/2 is real and positive. We assume that a is small, 
so that multi- photons are unlikely. Ignoring the small multi-photon component, the signals 
reside in a qutrit Hilbert space with basis {|vac), |0z), |lz)}; expanded in this basis, they may 
be re-expressed as 



\Q Z ) « e-^ 2 (l,V2 a,0 
|0x) « e^/ 2 (l, a, a) , 
\lz) « e~^ 2 (l,0,y/2a 



(i,o,v5 

\lx) « e^ /2 (l, a, -a) . (B.2) 



We will describe an intercept /resend attack on BB84 using these signals, based on un- 
ambiguous key discrimination. By exploiting her knowledge of the phase of the signals, Eve 
performs a POVM with three outcomes: 0, 1, and DK (don't know). The DK outcome is 
inconclusive, but if either of the other outcomes occurs, then Eve knows with certainty the 
key bit (0 or 1) encoded in the BB84 signal emitted by the source, though she does not gain 
any information about which of the two possible BB84 states compatible with that key bit 
was emitted. Eve blocks the signals when her outcome is DK, but if the outcome is conclusive 
she sends on to Bob a uniform coherent superposition of the two compatible BB84 states. 
This procedure generates a bit error rate S = | — w .146. Evidently, Eve has the same 
key information as Alice and Bob, so that, if she also knows their protocol for error correction 
and privacy amplification, she will have perfect knowledge of every bit of the final key. 

The multi-photon component of the state can help Eve, but to keep our analysis simple, we 
will consider an attack on this source that makes no use of the multi-photons. Eve performs an 
orthogonal measurement that distinguishes photon number less than two from photon number 
greater than or equal to two, and she discards the state if the latter outcome is found. (We 
will be interested in values of \i that are sufficiently small that Eve would not benefit very 
much from taking advantage of the multi-photons.) Thus the states she retains are qutrits. 
She then performs a three-outcome POVM (unambiguous key distribution) to identify the 
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key bit. The two conclusive outcomes of the POVM are projections onto the states: 

1 1 



|0 X > 
|1 X > 



-V2a-a, 1 + 



V2' V2 



1 1 



(B.3) 



where N^o, N^i are normalization factors such that 



N~ 2 



(2 + V2 



N~l = (2 + V2) 



1+ '2 



1 



2^ 
1 

2Vl 



(B.4) 



The vector 10^) is orthogonal to both of the two states \0z) and |0x) that indicate the key 
bit 0. Hence, if this outcome is found, Eve knows for sure that the key bit could not be 
and so must be 1. Similarly, the vector ll- 1 ) is orthogonal to both of the states \lz) and |lx) 
that indicate the key bit 1. 

The vectors lO -1 ) and ll -1 ) are nearly parallel for small a. To ensure that all three POVM 
elements are positive, we may choose 



E = 1 -\l ± )(l ± \, E 1 = ±\0 L )(0 L \ 



DK 



(B.5) 



(For small positive /i, the strength of the conclusive POVM elements can be pushed up slightly, 
but this is a small effect that we ignore.) Thus we find the probability pc of a conclusive 
outcome (taking into account that Eve might detect multi-photons and reject the state) 



(0z\E o \0z) - (0x\E \0 x ) 
'1 1 
2 2V2 



fj,e 



1 



2V2 



(B.6) 



if the key bit is 0, and 



(lz|£i|lz) 
1 1 



2V2 



(IxlE^lx) 
lie •- 1 



2V2 



-1 -1 



(B.7) 



if the key bit is 1. We note that the conclusive outcome is slightly more likely when the 
key bit is 1. This asymmetry can be traced to the property that the overlap |(0x|0z)| of 
the two signals that indicate the key bit is slightly larger than the overlap |(lx|lz)| of the 
two signals that indicate the key bit 1. (For other choices of the phase e tv that determines 
the plane in the Bloch sphere occupied by the BB84 signals, the asymmetry is substantially 
larger.) In any case, for either value of the key bit, the probability of a conclusive outcome 
obeys 

Pc > (.146)/ie-" [1 + {^hA)^- 1 . (B.8) 
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Now pc is the probability that Eve resends the signal to Bob, and therefore it is also the 
probability po that Bob detects a signal, if his detector is perfectly efficient. If there were 
no interference by the eavesdropper (and no loss in the quantum channel connecting Alice 
and Bob), all non-vacuum signals would be detected, and then pr> = 1 — e _A1 = fx + 0(/x 2 ). 
If Eve uses the unambiguous key discrimination POVM, then of course pc vanishes in the 
limit /i — > 0, but what is noteworthy is that pc vanishes linearly with /i. Thus for // small, 
a fraction r\ sa .146 of order one of all the non- vacuum signals sent by Alice are received by 
Bob. (Since multi-photon signals span a space of even higher dimension, there is a POVM — 
unambiguous state discrimination — that, when conclusive, identifies not just the key bit but 
also the basis |42| ; however for that POVM the probability of a conclusive outcome is higher 
order in /i.) 

Having characterized Eve's attack against a source that emits the signal set eq. (|B.1[) , let 
us now consider the security analysis of a phase-randomized source. We will refer to the source 
that emits weak coherent states with a definite phase known by the eavesdropper as source P 
(for phase), and to a source that emits phase-randomized weak coherent states, with the same 
mean photon number [i, as source R (for random). If source P emits the signals eq. (|B . 1[) . 
and Eve launches the intercept/resend attack using unambiguous key discrimination, then 
Eve has perfect knowledge of every key bit, and Alice and Bob detect a bit error rate of 
6 = .146. But if source R is used instead, we will see that Alice and Bob can extract private 
key at a nonzero asymptotic rate for a bit error rate up to 8 = .189. For the security analysis 
of source R, we will adopt a more restricted (and less realistic) model of the detector than 
the model described in Sec. [2j the detector applies a basis-independent "squash" that maps 
the incoming signal to a qubit, and then an ideal BB84 measurement is performed on that 
qubit in the appropriate basis. 

We suppose that the source emits a multi-photon signal with probability pm, that Bob 
detects a fraction pu of all the signals sent by Alice, and that Eve's attack is unrestricted. 
Of the signals that are received, the fraction that were emitted as multi-photons is no more 
than A = pm/pd] the rest are single photon signals. 

To establish a nonzero key generation rate for a relatively high bit error rate, we will 
need to consider schemes for key reconciliation and privacy amplification that involve two- 
way communication between Alice and Bob, for which the argument in .18] based on the 
uncertainty principle does not apply. Instead we can prove security following [5], by relating 
the BB84 protocol to a protocol in which the key is generated by measuring noisy entangled 
pairs shared by Alice and Bob. Private key can be extracted at a positive asymptotic rate if 
it is possible to distill high fidelity entanglement from the noisy entanglement. Entanglement 
distillation will succeed if the noisy entangled pairs have a bit error rate and a phase error rate 
that are both sufficiently small. The bit error rate 6 is inferred directly from the verification 
test in the BB84 protocol; the phase error rate S p is also inferred, but by a less direct argument. 

If the source and detector used in the protocol were perfect, then a symmetry argument 
would suffice to show 5 — S p . This symmetry is broken if the equipment is imperfect, but 
it is still possible to bound the difference between the two error rates using an appropriate 
characterization of the imperfections. For the case where Bob has a perfect detector, but 
Alice's source sometimes emits multi-photons, it can be shown as in eq. (|40p that 



\S P -S\< A/2 , 



(B.9) 
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where A is the fraction of all the detected signals that were emitted as multi-photons. Eq. (|40]) 
is an improvement found by Boileau [29] of the result |<5p — S\ = A found in [13] . 

The security proof in [5], which relates one-way privacy amplification to one-way entan- 
glement distillation using quantum error-correcting codes, does not apply for a bit error rate 
above S — .110. But security of BB84 was established in [43] for a bit error rate as high 
as .189, by relating two-way privacy amplification to entanglement distillation with two-way 
communication between Alice and Bob. The original argument in [43] assumed a perfect 
source and detector. But the two-way entanglement distillation succeeds if both S and S p are 
below .189; therefore the argument can be applied to a protocol with imperfect equipment if 
there is a strong enough bound on \5 — S p \. 

If the bit error rate 6 is .146, then the two-way BB84 protocol is secure for |<5 — S p \ < 
.189 — .146 = .043. And for a source that emits phase-randomized coherent states, it suffices 
that A < .086, where 

A = ^ < ( T ) 

Pd \(.U6)(xe-i*[l + (M4)n] 1 ) 

= (3.42)^e M [1 + (.854)/x] . (B.10) 

Thus A < .086, and the protocol is provably secure, for fi < .0240. The security proof 
still applies if Bob's detector, rather than being perfectly efficient, has an efficiency that is 
independent of the basis in which the detector measures, where whether the detector fires is 
decided randomly, uninfluenced by the eavesdropper }44] . 

We have shown, therefore, that the BB84 QKD protocol is less secure using the phase- 
coherent source P than using the phase-randomized source R. Eve can exploit her knowledge 
of the phase of the signals emitted by the source P to implement a POVM that, when its 
outcome is conclusive, unambiguously identifies the key bit. But for the same bit error rate 
5 w .146, signal strength /i (< .0240), and signal detection rate po ~ .146/i, if the signals have 
random phases then Alice and Bob can generate a final key about which Eve has negligible 
knowledge. 

In fact, for source P using the signal set eq. (|B. 1[) we do not have a security proof that 
establishes any positive bit error rate 6 such that provably secure key can be generated at a 
positive asymptotic rate. However, as we have emphasized, it is a different story for the signal 
set eq. ©. In this paper, we have proven the security of BB84 using these signals, even when 
Eve knows the phase of the reference pulse. 



